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In the Claims 

Please replace all prior versions, and listings, of claims in the application with the 
following list of claims: 

1 . (Original) A method for use in a computer system including a plurality of devices, a 
shared resource shared by the plurality of devices, and a network that couples the plurality of 
devices to the shared resource, the method including acts of: 

(a) in response to one of the plurality of devices attempting to access the shared 
resource and representing itself to the shared resource as a first device, determining whether the 
one of the plurality of devices is attempting to access the shared resource through a physical 
connection through the network that is different than a first physical connection through the 
network used by the first device to access the shared resource; and 

(b) when it is determined in the act (a) that the one of the plurality of devices is 
attempting to access the shared resource through a connection through the network that is 
different than the first physical connection, denying the attempted access by the one of the 
plurality of devices to the shared resource. 

2. (Original) The method of claim 1, wherein the attempted access by the one of the 
plurality of devices is an attempt to login to the shared resource, and wherein the act (b) includes 
an act of: 

when it is determined in the act (a) that the one of the plurality of devices is attempting to 
login to the shared resource through a physical connection through the network that is different 
than the first physical connection, denying the attempted login by the one of the plurality of 
devices to the shared resource. 

3. (Original) The method of claim 1, wherein the network is a Fibre Channel fabric, 
wherein the one of the plurality of devices and the first device each has an assigned world wide 
name (WWN) and a fabric identifier (fabric ID); 

wherein the method further includes a step of storing the WWN and the fabric ID of the 
first device in response to an access by the first device to the shared resource; and 
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wherein the act (a) is performed in response to an access, that occurs after the access by 
the first device, by the one of the plurality of devices to the shared resource and includes acts of: 

examining a value of the WWN presented by the one of the plurality of devices to 
the shared resource to determine that the one of the plurality of devices is representing 
itself as being the first device; 

comparing a value of the fabric ID presented by the one of the plurality of devices 
to the stored fabric ID for the first device; and 

determining that the one of the plurality of devices is attempting to access the 
shared resource through a physical connection through the network that is different than 
the first physical connection when the value of the fabric ID presented by the one of the 
plurality of devices mismatches the stored fabric ID for the first device. 

4. (Original) The method of claim 1, wherein the network employs a protocol wherein the 
one of the plurality of devices and the first device each has a first identifier that uniquely 
identifies the device in a manner that is independent of a physical configuration of the computer 
system and a second identifier that uniquely identifies the device in a manner that is dependent 
upon the physical configuration of the computer system; 

wherein the method further includes a step of storing the first and second identifiers of 
the first device in response to an access by the first device to the shared resource; and 

wherein the act (a) is performed in response to an access, that occurs after the access by 
the first device, by the one of the plurality of devices to the shared resource and includes acts of: 
examining a value of the first identifier presented by the one of the plurality of 

devices to the shared resource to determine that the one of the plurality of devices is 

representing itself to be the first device; 

comparing a value of the second identifier presented by the one of the plurality of 

devices to the stored value of the second identifier for the first device; and 

determining that the one of the plurality of devices is attempting to access the 

shared resource through a physical connection through the network that is different than 

the first physical connection when the value of the second identifier presented by the one 

of the plurality of devices mismatches the stored value of the second identifier for the 

first device. 
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5. (Original) The method of claim 1, wherein the shared resource is a storage system; 
wherein the act (a) includes an act of, in response to the one of the plurality of devices 

attempting to access the storage system and representing itself to the storage system as the first 
device, determining whether the one of the plurality of devices is attempting to access the storage 
system through a physical connection through the network that is different than a first physical 
connection through the network that the first device uses to access the storage system; and 

wherein the act (b) includes an act of, when it is determined in the act (a) that the one of 
the plurality of devices is attempting to access the storage system through a physical connection 
through the network that is different than the first physical connection, denying the attempted 
access by the one of the plurality of devices to the storage system. 

6. (Original) The method of claim 5, wherein the acts (a) and (b) are performed by the 
storage system. 

7. (Original) The method of claim 5, wherein the acts (a) and (b) are performed outside of 
the storage system. 

8. (Original) The method of claim 7, wherein the acts (a) and (b) are performed by a device 
disposed between the storage system and the network. 

9. (Original) The method of claim 2, wherein the network is a Fibre Channel fabric, 
wherein the one of the plurality of devices and the first device each has an assigned world wide 
name (WWN) and a fabric identifier (fabric ID); 

wherein the method further includes a step of storing the WWN and the fabric ID of the 
first device in response to a login by the first device to the shared resource; and 

wherein the act (a) is performed in response to a login attempt, that occurs after the login 
by the first device, by the one of the plurality of devices to the shared resource and includes acts 
of: 
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examining a value of the WWN presented by the one of the plurality of devices to 
the shared resource to determine that the one of the plurality of devices is representing 
itself as being the first device; 

comparing a value of the fabric ID presented by the one of the plurality of devices 
to the stored fabric ID for the first device; and 

determining that the one of the plurality of devices is attempting to login to the 
shared resource through a physical connection through the network that is different than 
the first physical connection when the value of the fabric ID presented by the one of the 
plurality of devices mismatches the stored fabric ID for the first device. 

10. (Original) The method of claim 9, wherein the shared resource is a storage system; 
wherein the act (a) includes an act of, in response to the one of the plurality of devices 

attempting to login to the storage system and representing itself to the storage system as the first 
device, determining whether the one of the plurality of devices is attempting to login to the 
storage system through a physical connection through the network that is different than a first 
physical connection through the network used by the first device to access the storage system; 
and 

wherein the act (b) includes an act of, when it is determined in the act (a) that the one of 
the plurality of devices is attempting to login to the storage system through a physical connection 
through the network that is different than the first physical connection, denying the attempted 
login by the one of the plurality of devices to the storage system. 

1 1 . (Original) The method of claim 10, wherein the acts (a) and (b) are performed by the 
storage system. 

12. (Original) The method of claim 10, wherein the acts (a) and (b) are performed by a 
device disposed between the storage system and the network. 

13. (Original) The method of claim 2, wherein the network employs a protocol wherein the 
one of the plurality of devices and the first device each has a first identifier that uniquely 
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identifies the device in a manner that is independent of a physical configuration of the computer 
system and a second identifier that uniquely identifies the device in a manner that is dependent 
upon the physical configuration of the computer system; 

wherein the method further includes a step of storing the first and second identifiers of 
the first device in response to a login by the first device to the shared resource; and 

wherein the act (a) is performed in response to a login request, that occurs after the login 
by the first device, by the one of the plurality of devices to the shared resource and includes acts 
of: 

examining a value of the first identifier presented by the one of the plurality of 
devices to the shared resource to determine that the one of the plurality of devices is 
representing itself to be the first device; 

comparing a value of the second identifier presented by the one of the plurality of 
devices to the stored value of the second identifier for the first device; and 

determining that the one of the plurality of devices is attempting to login to the 
shared resource through a physical connection through the network that is different than 
the first physical connection when the value of the second identifier presented by the one 
of the plurality of devices mismatches the stored value of the second identifier for the 
first device. 

14. (Original) The method of claim 13, wherein the shared resource is a storage system; 

wherein the act (a) includes an act of, in response to the one of the plurality of devices 
attempting to login to the storage system and representing itself to the storage system as the first 
device, determining whether the one of the plurality of devices is attempting to login to the 
storage system through a physical connection through the network that is different than a first 
physical connection through the network used by the first device to access the storage system; 
and 

wherein the act (b) includes an act of, when it is determined in the act (a) that the one of 
the plurality of devices is attempting to login to the storage system through a physical connection 
through the network that is different than the first physical connection, denying the attempted 
login by the one of the plurality of devices to the storage system. 
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15. (Original) The method of claim 14, wherein the acts (a) and (b) are performed by the 
storage system. 

16. (Original) The method of claim 14, wherein the acts (a) and (b) are performed by a 
device disposed between the storage system and the network. 

17. (Original) The method of claim 3, wherein the shared resource is a storage system; 
wherein the act (a) includes an act of, in response to the one of the plurality of devices -j 

attempting to access the storage system and representing itself to the storage system as a first 
device, determining whether the one of the plurality of devices is attempting to access the storage 
system through a physical connection through the network that is different than a first physical 
connection through the network used by the first device to access the storage system; and 

wherein the act (b) includes an act of, when it is determined in the act (a) that the one of 
the plurality of devices is attempting to access the storage system through a physical connection 
through the network that is different than the first physical connection, denying the attempted 
access by the one of the plurality of devices to the storage system. 

18. (Original) The method of claim 17, wherein the acts (a) and (b) are performed by the 
storage system. 

19. (Original) The method of claim 17, wherein the acts (a) and (b) are performed by a 
device disposed between the storage system and the network. 

20. (Original) The method of claim 4, wherein the shared resource is a storage system; 
wherein the act (a) includes an act of, in response to the one of the plurality of devices 

attempting to access the storage system and representing itself to the storage system as a first 
device, determining whether the one of the plurality of devices is attempting to access the storage 
system through a physical connection through the network that is different than a first physical 
connection through the network used by the first device to access the storage system; and 

wherein the act (b) includes an act of, when it is determined in the act (a) that the one of 
the plurality of devices is attempting to access the storage system through a physical connection 
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through the network that is different than the first physical connection, denying the attempted 
access by the one of the plurality of devices to the storage system. 

21. (Original) The method of claim 20, wherein the acts (a) and (b) are performed by the 
storage system. 

22. (Original) The method of claim 20, wherein the acts (a) and (b) are performed by a 
device disposed between the storage system and the network. 

23. (Original) A method for use in a computer system including a plurality of devices, a 
storage system shared by the plurality of devices, and a network that couples the plurality of 
devices to the storage system, wherein the network employs a protocol wherein each of the 
plurality of devices has a first identifier that uniquely identifies the device in a manner that is 
independent of a physical configuration of the computer system and a second identifier that 
uniquely identifies the device in a manner that is dependent upon the physical configuration of 
the computer system, the method including acts of: 

(a) in response to a login of a first device of the plurality of devices to the storage 
system, storing the first and second identifiers of the first device; 

(b) in response to an attempt, subsequent to the act (a), by one of the plurality of 
devices to login to the storage system while representing itself to the storage system as the first 
device, determining whether the one of the plurality of devices is attempting to login to the 
storage system through a physical connection through the network that is different than a first 
physical connection through the network used by the first device to login to the storage system in 
the act (a), including acts of; 

(bl) examining a value of the first identifier presented by the one of the 
plurality of devices to the storage system to determine that the one of the plurality of 
devices is representing itself to be the first device; 

(b2) comparing a value of the second identifier presented by the one of the 
plurality of devices to the stored value of the second identifier for the first device; and 

(b3) determining that the one of the plurality of devices is attempting to login 
to the storage system through a physical connection through the network that is different 
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than the first physical connection when the value of the second identifier presented by the 
one of the plurality of devices mismatches the stored value of the second identifier for the 
first device; and 

(c) when it is determined in the act (b3) that the one of the plurality of devices is 
attempting to login to the storage system through a physical connection through the network that 
is different than the first physical connection, denying the attempted login by the one of the 
plurality of devices to the storage system. 

24. (Original) The method of claim 23, wherein the network is a Fibre Channel fabric, 
wherein the first identifier is a world wide name (WWN) and the second identifier is a fabric 
identifier (fabric ID); 

wherein the act (a) includes an act of, in response to a login of first device to the storage 
system, storing the WWN and the fabric ID of the first device; 

wherein the act (bl) includes an act of examining a value of the WWN presented by the 
one of the plurality of devices to determine that the one of the plurality of devices is representing 
itself to be the first device; 

wherein the act (b2) includes an act of comparing a value of the fabric ID presented by 
the one of the plurality of devices to the stored value of the fabric ID for the first device; and 

wherein the act (b3) includes an act of determining that the one of the plurality of devices 
is attempting to login to the storage system through a physical connection through the network 
that is different than the first physical connection when the value of the fabric ID presented by 
the one of the plurality of devices mismatches the stored value of the fabric ID for the first 
device. 

25. (Original) The method of claim 23, wherein the acts (a) and (b) are performed by the 
storage system. 

26. (Original) The method of claim 23, wherein the acts (a) and (b) are performed by a 
device disposed between the storage system and the network. 



Serial No.: 09/748,053 - 10 - Art Unit: 2134 

Conf.No.:4482 

27. (Original) A method for use in a computer system including a network and a plurality of 
devices coupled to the network, the network employing a protocol wherein each of the plurality 
of devices has a first identifier that uniquely identifies the device in a manner that is independent 
of a physical configuration of the computer system and a second identifier that uniquely 
identifies the device in a manner that is dependent upon the physical configuration of the 
computer system, the network including at least one network component that assigns a unique 
value for the second identifier to each of the plurality of devices that is logged into the network, 
the method including acts of: 

(a) in response to one of the plurality of devices attempting to login to the network 
and representing itself to the network as a first device, determining whether the one of the 
plurality of devices is attempting to login to the network through a port that is different than a 
first port of the network through which the first device previously logged into the network; and 

(b) when it is determined in the act (a) that the one of the plurality of devices is 
attempting to access the network through a port that is different than the first port, denying the 
attempted login by the one of the plurality of devices to the network. 

28. (Original) The method of claim 27, wherein the at least one network component includes 
at least one switch having a first switch port that forms the first port through which the first 
device previously logged into the network; and 

wherein the act (a) includes an act of, in response to the one of the plurality of devices 
attempting to login to the network and representing itself to the network as the first device, 
determining whether the one of the plurality of devices is attempting to login to the network 
through a port different than the first switch port. 

29. (Original) The method of claim 27, further including an act of preventing at least one of 
the plurality of devices from transmitting information through the network while representing 
itself with a value for the second identifier that differs from its value assigned by the at least one 
network component. 
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30. (Original) The method of claim 27, wherein the network is a Fibre Channel fabric, 
wherein the first identifier is a world wide name (WWN) and the second identifier is a fabric 
identifier (fabric ID); 

wherein the method further includes an act of, in response to the previous login of the 
first device into the network, storing the WWN and the fabric ID of the first device; and 
wherein the act (a) includes acts of; 

examining a value of the WWN presented by the one of the plurality of devices 
during the attempted login to determine that the one of the plurality of devices is 
representing itself to be the first device; 

comparing a value of the fabric ID presented by the one of the plurality of devices 
to the stored value of the fabric ID for the first device; and 

determining that the one of the plurality of devices is attempting to access the 
network through a port that is different than the first port when the value of the fabric ID 
presented by the one of the plurality of devices mismatches the stored value of the fabric 
ID for the first device. 

3 1 . (Original) The method of claim 27, wherein the method further includes an act of, in 
response to the previous login of the first device into the network, storing the first and second 
identifiers of the first device; and 

wherein the act (a) includes acts of; 

examining a value of the first identifier presented by the one of the plurality of 
devices during the attempted login to determine that the one of the plurality of devices is 
representing itself to be the first device; 

comparing a value of the second identifier presented by the one of the plurality of 
devices to the stored value of the second identifier for the first device; and 

determining that the one of the plurality of devices is attempting to access the 
network through a port different than the first port when the value of the second identifier 
presented by the one of the plurality of devices mismatches the stored value of the second 
identifier for the first device. 
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32. (Original) An apparatus for use in a computer system including a plurality of devices, a 
shared resource shared by the plurality of devices, and a network that couples the plurality of 
devices to the shared resource, the apparatus including: 

an input to be coupled to the network; and 

at least one controller, coupled to the input, that is responsive to one of the plurality of 
devices attempting to access the shared resource while representing itself to the shared resource 
as a first device, to determine whether the one of the plurality of devices is attempting to access 
the shared resource through a physical connection through the network that is different than a 
first physical connection through the network used by the first device to access the shared 
resource, and to deny the attempted access by the one of the plurality of devices to the shared 
resource when it is determined that the one of the plurality of devices is attempting to access the 
shared resource through a physical connection through the network that is different than the first 
physical connection. 

33. (Original) The apparatus of claim 32, wherein the attempted access by the one of the 
plurality of devices is an attempt to login to the shared resource, and wherein the at least one 
controller denies the attempted login when it is determined that the one of the plurality of devices 
is attempting to login to the shared resource through a physical connection through the network 
that is different than the first physical connection. 

34. (Original) The apparatus of claim 32, wherein the network is a Fibre Channel fabric, 
wherein the one of the plurality of devices and the first device each has an assigned world wide 
name (WWN) and a fabric identifier (fabric ID); 

wherein the apparatus further includes a storage device coupled to the at least one 
controller; 

wherein the at least one controller stores the WWN and the fabric ID of the first device in 
the storage device in response to an access by the first device to the shared resource; and 

wherein when the one of the plurality of devices attempts to access the shared resource 
after the access by the first device, the at least one controller: 
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examines a value of the WWN presented by the one of the plurality of devices to 
the shared resource to determine that the one of the plurality of devices is representing 
itself as being the first device; 

compares a value of the fabric ID presented by the one of the plurality of devices 
to the stored fabric ID for the first device; and 

determines that the one of the plurality of devices is attempting to access the 
shared resource through a physical connection through the network that is different than 
the first physical connection when the value of the fabric ID presented by the one of the 
plurality of devices mismatches the stored fabric ID for the first device. 

35. (Original) The apparatus of claim 32, wherein the network employs a protocol wherein 
the one of the plurality of devices and the first device each has a first identifier that uniquely 
identifies the device in a manner that is independent of a physical configuration of the computer 
system and a second identifier that uniquely identifies the device in a manner that is dependent 
upon the physical configuration of the computer system; 

wherein the apparatus further includes a storage device coupled to the at least one 
controller; 

wherein the at least one controller stores the first and second identifiers of the first device 
in the storage device in response to an access by the first device to the shared resource; and 

wherein when the one of the plurality of devices attempts to access the shared resource 
after the access by the first device, the at least one controller: 

examines a value of the first identifier presented by the one of the plurality of 
devices to the shared resource to determine that the one of the plurality of devices is 
representing itself to be the first device; 

compares a value of the second identifier presented by the one of the plurality of 
devices to the stored value of the second identifier for the first device; and 

determines that the one of the plurality of devices is attempting to access the 
shared resource through a physical connection through the network that is different than 
the first physical connection when the value of the second identifier presented by the one 
of the plurality of devices mismatches the stored value of the second identifier for the 
first device. 



Serial No.: 09/748,053 - 14 - Art Unit: 2134 

Conf. No.: 4482 

36. (Original) The apparatus of claim 32, wherein the shared resource is a storage system; 
wherein in response to the one of the plurality of devices attempting to access the storage 

system and representing itself to the storage system as a first device, the at least one controller 
determines whether the one of the plurality of devices is attempting to access the storage system 
through a physical connection through the network that is different than the first physical 
connection; and 

wherein when it is determined that the one of the plurality of devices is attempting to 
access the storage system through a physical connection through the network that is different 
than the first physical connection, the at least one controller denies the attempted access by the 
one of the plurality of devices to the storage system. 

37. (Original) The apparatus of claim 36, in combination with the storage system, wherein 
the at least one controller and the input each is disposed within the storage system. 

38. (Original) The apparatus of claim 36, wherein the at least one controller and the input 
each is disposed outside of the storage system. 

39. (Original) The apparatus of claim 38, wherein the apparatus includes a filter unit that 
includes the input and the at least one controller and is adapted to be disposed between the 
storage system and the network. 

40. (Original) The apparatus of claim 33, wherein the network is a Fibre Channel fabric, 
wherein the one of the plurality of devices and the first device each has an assigned world wide 
name (WWN) and a fabric identifier (fabric ID); 

wherein the at least one controller stores the WWN and the fabric ID of the first device in 
response to a login by the first device to the shared resource; and 

wherein when the one of the plurality of devices attempts to login to the shared resource 
after the login by the first device, the at least one controller: 
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examines a value of the WWN presented by the one of the plurality of devices to 
the shared resource to determine that the one of the plurality of devices is representing 
itself as being the first device; 

compares a value of the fabric ID presented by the one of the plurality of devices 
to the stored fabric ID for the first device; and 

determines that the one of the plurality of devices is attempting to login to the 
shared resource through a physical connection through the network that is different than 
the first physical connection when the value of the fabric ID presented by the one of the 
plurality of devices mismatches the stored fabric ID for the first device. 

41. (Original) The apparatus of claim 40, wherein the shared resource is a storage system; 
wherein in response to the one of the plurality of devices attempting to login to the 

storage system and representing itself to the storage system as a first device, the at least one 
controller determines whether the one of the plurality of devices is attempting to login to the 
storage system through a physical connection through the network that is different than the first 
physical connection; and 

wherein when it is determined that the one of the plurality of devices is attempting to 
login to the storage system through a physical connection through the network that is different 
than the first physical connection, the at least one controller denies the attempted login by the 
one of the plurality of devices to the storage system. 

42. (Original) The apparatus of claim 41, in combination with the storage system, wherein 
the at least one controller and the input each is disposed within the storage system. 

43. (Original) The apparatus of claim 41, wherein the apparatus includes a filter unit that 
includes the input and the at least one controller and is adapted to be disposed between the 
storage system and the network. 

44. (Original) The apparatus of claim 33, wherein the network employs a protocol wherein 
the one of the plurality of devices and the first device each has a first identifier that uniquely 
identifies the device in a manner that is independent of a physical configuration of the computer 
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system and a second identifier that uniquely identifies the device in a manner that is dependent 
upon the physical configuration of the computer system; 

wherein the apparatus further includes a storage device coupled to the at least one 
controller; 

wherein the at least one controller stores the first and second identifiers of the first device 
in the storage device in response to a login by the first device to the shared resource; and 

wherein when the one of the plurality of devices attempts to login to the shared resource 
after the login by the first device, the at least one controller: 

examines a value of the first identifier presented by the one of the plurality of 
devices to the shared resource to determine that the one of the plurality of devices is 
representing itself to be the first device; 

compares a value of the second identifier presented by the one of the plurality of 
devices to the stored value of the second identifier for the first device; and 

determines that the one of the plurality of devices is attempting to login to the 
shared resource through a physical connection through the network that is different than 
the first physical connection when the value of the second identifier presented by the one 
of the plurality of devices mismatches the stored value of the second identifier for the 
first device. 

45. (Original) The apparatus of claim 44, wherein the shared resource is a storage system; 

wherein in response to the one of the plurality of devices attempting to login to the 
storage system and representing itself to the storage system as a first device, the at least one 
controller determines whether the one of the plurality of devices is attempting to login to the 
storage system through a physical connection through the network that is different than the first 
physical connection; and 

wherein when it is determined that the one of the plurality of devices is attempting to 
login to the storage system through a physical connection through the network that is different 
than the first physical connection, the at least one controller denies the attempted login by the 
one of the plurality of devices to the storage system. 
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46. (Original) The apparatus of claim 45, in combination with the storage system, wherein 
the at least one controller and the input each is disposed within the storage system. 

47. (Original) The apparatus of claim 45, wherein the apparatus includes a filter unit that 
includes the input and the at least one controller and is adapted to be disposed between the 
storage system and the network. 

48. (Original) The apparatus of claim 34, wherein the shared resource is a storage system; 
wherein in response to the one of the plurality of devices attempting to access the storage 

system and representing itself to the storage system as a first device, the at least one controller 
determines whether the one of the plurality of devices is attempting to access the storage system 
through a physical connection through the network that is different than the first physical 
connection; and 

wherein when it is determined that the one of the plurality of devices is attempting to 
access the storage system through a physical connection through the network that is different 
than the first physical connection, the at least one controller denies the attempted access by the 
one of the plurality of devices to the storage system. 

49. (Original) The apparatus of claim 48, in combination with the storage system, wherein 
the at least one controller and the input each is disposed within the storage system. 

50. (Original) The apparatus of claim 48, wherein the apparatus includes a filter unit that 
includes the input and the at least one controller and is adapted to be disposed between the 
storage system and the network. 

51. (Original) The apparatus of claim 35, wherein the shared resource is a storage system; 
wherein in response to the one of the plurality of devices attempting to access the storage 

system and representing itself to the storage system as a first device, the at least one controller 
determines whether the one of the plurality of devices is attempting to access the storage system 
through a physical connection through the network that is different than the first physical 
connection; and 
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wherein when it is determined that the one of the plurality of devices is attempting to 
access the storage system through a physical connection through the network that is different 
than the first physical connection, the at least one controller denies the attempted access by the 
one of the plurality of devices to the storage system. 

52. (Original) The apparatus of claim 51, in combination with the storage system, wherein 
the at least one controller and the input each is disposed within the storage system. 

53. (Original) The apparatus of claim 5 1 , wherein the apparatus includes a filter unit that 
includes the input and the at least one controller and is adapted to be disposed between the 
storage system and the network. 

54. (Original) The apparatus of claim 32, wherein the at least one controller includes: 
means, responsive to the one of the plurality of devices attempting to access the shared 

resource while representing itself to the shared resource as a first device, for determining 
whether the one of the plurality of devices is attempting to access the shared resource through a 
physical connection through the network that is different than a first physical connection through 
the network used by the first device to access the shared resource; and 

means for denying the attempted access by the one of the plurality of devices to the 
shared resource when it is determined that the one of the plurality of devices is attempting to 
access the shared resource through a physical connection through the network that is different 
than the first physical connection. 

55. (Original) The apparatus of claim 33, wherein the shared resource is a storage system; 
wherein in response to the one of the plurality of devices attempting to login to the 

storage system and representing itself to the storage system as a first device, the at least one 
controller determines whether the one of the plurality of devices is attempting to login to the 
storage system through a physical connection through the network that is different than the first 
physical connection; and 

wherein when it is determined that the one of the plurality of devices is attempting to 
login to the storage system through a physical connection through the network that is different 
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than the first physical connection, the at least one controller denies the attempted login by the 
one of the plurality of devices to the storage system. 

56. (Original) The method of claim 2, wherein the shared resource is a storage system; 
wherein the act (a) includes an act of, in response to the one of the plurality of devices 

attempting to login to the storage system and representing itself to the storage system as the first 
device, determining whether the one of the plurality of devices is attempting to login to the 
storage system through a physical connection through the network that is different than a first 
physical connection through the network that the first device uses to login to the storage system; 
and 

wherein the act (b) includes an act of, when it is determined in the act (a) that the one of 
the plurality of devices is attempting to login to the storage system through a physical 
connection through the network that is different than the first physical connection, denying the 
attempted login by the one of the plurality of devices to the storage system. 

57. (Original) An apparatus for use in a computer system including a plurality of devices, a 
storage system shared by the plurality of devices, and a network that couples the plurality of 
devices to the storage system, wherein the network employs a protocol wherein each of the 
plurality of devices has a first identifier that uniquely identifies the device in a manner that is 
independent of a physical configuration of the computer system and a second identifier that 
uniquely identifies the device in a manner that is dependent upon the physical configuration of 
the computer system, the apparatus comprising: 

an input to be coupled to the network; 
a storage device; and 

at least one controller, coupled to the network and the storage device, that is responsive to 
a login of a first device of the plurality of devices to the storage system to store the first and 
second identifiers of the first device in the storage device; 

the at least one controller further being responsive to an attempt, after the login by the 
first device, by one of the plurality of devices to login to the storage system, while representing 
itself to the storage system as the first device, to; 
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examine a value of the first identifier presented by the one of the plurality of 
devices to the storage system to determine that the one of the plurality of devices is 
representing itself to be the first device; 

compare a value of the second identifier presented by the one of the plurality of 
devices to the stored value of the second identifier for the first device; 

determine that the one of the plurality of devices is attempting to access the 
storage system through a physical connection through the network that is different than a 
first physical connection used by the first device in logging into the storage system when 
the value of the second identifier presented by the one of the plurality of devices 
mismatches the stored value of the second identifier for the first device; and 

deny the attempted login by the one of the plurality of devices to the storage 
system when it is determined that the one of the plurality of devices is attempting to login 
to the storage system through a physical connection through the network that is different 
than the first physical connection. 

58. (Original) The apparatus of claim 57, wherein the network is a Fibre Channel fabric, 
wherein the first identifier is a world wide name (WWN) and the second identifier is a fabric 
identifier (fabric ID); 

wherein the at least one controller stores the WWN and the fabric ID of the first device in 
the storage device in response to the login by the first device to the storage system; and 

wherein when the one of the plurality of devices attempts to login to the storage system 
after the login by the first device, the at least one controller: 

examines a value of the WWN presented by the one of the plurality of devices to 
the storage system to determine that the one of the plurality of devices is representing 
itself as being the first device; 

compares a value of the fabric ID presented by the one of the plurality of devices 
to the stored fabric ID for the first device; and 

determines that the one of the plurality of devices is attempting to access the 
storage system through a physical connection through the network that is different than 
the first physical connection when the value of the fabric ID presented by the one of the 
plurality of devices mismatches the stored fabric ID for the first device. 
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59. (Original) The apparatus of claim 57, in combination with the storage system, wherein 
the at least one controller, the storage device and the input each is disposed within the storage 
system. 

60. (Original) The apparatus of claim 57, further including a filter unit that includes the input 
and the at least one controller and is adapted to be disposed between the storage system and the 
network. 

61 . (Original) The apparatus of claim 57, wherein the at least one controller includes: 
means, responsive to the login of a first device of the plurality of devices to the storage 

system, to store the first and second identifiers of the first device in the storage device; 

means, responsive to an attempt, after the login by the first device, by one of the plurality 
of devices to login to the storage system, while representing itself to the storage system as the 
first device, for examining a value of the first identifier presented by the one of the plurality of 
devices to the storage system to determine that the one of the plurality of devices is representing 
itself to be the first device and for comparing a value of the second identifier presented by the 
one of the plurality of devices to the stored value of the second identifier for the first device; 

means for determining that the one of the plurality of devices is attempting to access the 
storage system through a physical connection through the network that is different than a first 
physical connection used by the first device in logging into the storage system when the value of 
the second identifier presented by the one of the plurality of devices mismatches the stored value 
of the second identifier for the first device; and 

means for denying the attempted login by the one of the plurality of devices to the storage 
system when it is determined that the one of the plurality of devices is attempting to login to the 
storage system through a physical connection through the network that is different than the first 
physical connection. 

62. (Original) An apparatus for use in a computer system including a network and a plurality 
of devices coupled to the network, the network employing a protocol wherein each of the 
plurality of devices has a first identifier that uniquely identifies the device in a manner that is 
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independent of a physical configuration of the computer system and a second identifier that 
uniquely identifies the device in a manner that is dependent upon the physical configuration of 
the computer system, the network including at least one network component that assigns a 
unique value for the second identifier to each of the plurality of devices that is logged into the 
network, the apparatus comprising: 

at least one input to be coupled to at least one of the plurality of devices; and 
at least one controller that is responsive to one of the plurality of devices attempting to 
login to the network and representing itself to the network as a first device, to determine whether 
the one of the plurality of devices is attempting to login to the network through a port that is 
different than a first port of the network through which the first device previously logged into the 
network, and to deny the attempted login by the one of the plurality of devices to the network 
when the one of the plurality of devices is attempting to login to the network through a port that 
is different than the first port. 

63. (Original) The apparatus of claim 62, in combination with a network switch to form at 
least a portion of the network, wherein the at least one controller is disposed within the 
switch. 

64. (Original) The apparatus of claim 62, wherein the at least one controller prevents at least 
one of the plurality of devices from transmitting information through the network while 
representing itself with a value for the second identifier that differs from its value assigned by the 
at least one network component. 

65. (Original) The apparatus of claim 62, wherein the network is a Fibre Channel fabric, 
wherein the first identifier is a world wide name (WWN) and the second identifier is a fabric 
identifier (fabric ID); 

wherein the apparatus further includes a storage device coupled to the at least one 
controller; 

wherein the at least one controller stores the WWN and the fabric ID of the first device in 
response to the login of the first device into the network; and 
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wherein when the one of the plurality of devices attempts to login to the shared resource 
after the login by the first device, the at least one controller: 

examines a value of the WWN presented by the one of the plurality of devices 
during the attempted login to determine that the one of the plurality of devices is 
representing itself to be the first device; 

compares a value of the fabric ID presented by the one of the plurality of devices 
to the stored value of the fabric ID for the first device; and 

determines that the one of the plurality of devices is attempting to access the 
network through a port that is different than the first port when the value of the fabric ID 
presented by the one of the plurality of devices mismatches the stored value of the fabric 
ID for the first device. 

66. (Original) The apparatus of claim 62, wherein the apparatus further includes a storage 
device coupled to the at least one controller; 

wherein the at least one controller stores the first and second identifiers of the first device 
in response to the login of the first device into the network; and 

wherein when the one of the plurality of devices attempts to login to the shared resource 
after the login by the first device, the at least one controller: 

examines a value of the first identifier presented by the one of the plurality of 

devices during the attempted login to determine that the one of the plurality of devices is 

representing itself to be the first device; 

compares a value of the second identifier presented by the one of the plurality of 

devices to the stored value of the second identifier for the first device; and 

determines that the one of the plurality of devices is attempting to access the 

network through a port different than the first port when the value of the second identifier 

presented by the one of the plurality of devices mismatches the stored value of the second 

identifier for the first device. 



